Legal
Acceptable Use Policy
Last updated
The house rules for the MazeCrafts player app, facilitator uploads and physical maze installations, plus how we enforce them.
1. Scope and purpose
This Acceptable Use Policy applies to everyone who touches a MazeCrafts service: workspace administrators, facilitators, players in the mobile app, event agencies operating on a customer’s behalf, and anyone using the API. It forms part of the Terms and Conditions. Its purpose is narrow and practical: a team-building event should be safe, dignified and technically stable for everybody in the room, including the colleague who did not choose to be there.
The customer named on the licence is accountable for the conduct of its participants and for briefing them on these rules before a run begins. Facilitators must acknowledge this policy in the console before starting their first event.
2. Prohibited content in uploads
The facilitator console accepts custom clue text, images, audio, team rosters and white-label logos. You must not upload content that:
- infringes copyright, trade marks, design rights or database rights, including stock photography used outside its licence;
- contains sexual material, graphic violence, or gratuitous shock imagery;
- promotes hatred, discrimination or violence on the basis of race, ethnic origin, nationality, religion, disability, age, sex, sexual orientation or gender identity;
- discloses another person’s private information — home address, medical details, private messages, identity documents — without a lawful basis and their knowledge;
- includes special categories of personal data under Article 9 GDPR, such as health or union membership, in puzzle content;
- contains malware, obfuscated scripts, deceptive links, or QR codes pointing at credential-harvesting pages;
- impersonates a colleague, executive or public figure in a way likely to deceive;
- constitutes a covert test of colleagues, such as a phishing simulation dressed as a puzzle, unless it has documented approval from the customer’s security and people functions.
Uploaded files are scanned for malware. We do not read your clue text routinely, and human review happens only after a report or an automated signal.
3. Prohibited conduct in the player app
- Harassment, threats, sexual advances, slurs or sustained personal mockery in team chat or hint requests.
- Sharing solution keys or scraped answer sets with other teams, or publishing them anywhere outside the event.
- Using another person’s credentials, or joining a run you were not invited to.
- Automating gameplay with scripts, emulators or bots, or manipulating timers and scoreboards.
- Recording or photographing participants who have asked not to be captured, and re-publishing event footage without consent.
- Bypassing rate limits, licence checks, watermarking or the concurrency ceiling.
- Probing, scanning or stress-testing our infrastructure outside the terms of clause 6.
4. Dignity, participation and pressure
Team building goes wrong when it becomes an assessment. Customers must not use MazeCrafts results for performance appraisal, promotion decisions, redundancy selection or disciplinary purposes; our engagement reports are descriptive and are contractually unsuitable for those uses. Participation must be genuinely voluntary where an event falls outside working hours. Facilitators must offer a non-physical role — radio operator, note taker, timekeeper — to anyone who prefers it, and must never announce a medical reason for an accommodation.
No player may be required to disclose personal information, consume alcohol, submit to blindfolding or restraint, or be filmed as a condition of taking part. Puzzle themes involving confinement, darkness, surveillance or medical scenarios must be flagged in the pre-event briefing.
5. Safety rules for physical mazes
Physical installations introduce real-world risk, so these rules are mandatory and not waivable:
- Egress: every cell must have an unobstructed exit route that opens without solving a puzzle. Doors are never locked with players inside; magnetic hold-open devices must fail open on power loss.
- Occupancy: a maximum of one player per 1.5 square metres of floor area, and never more than the venue’s posted occupancy figure.
- Structural load: free-standing maze walls are rated to 15 kg of lateral load and must be ballasted per the assembly guide; climbing, sitting or leaning on walls is prohibited, and props may not be suspended from sprinkler pipes, cable trays or ceiling grids.
- Lighting and floor: minimum 20 lux on all walking surfaces, cables taped or ramped, no trip hazards across a route.
- Supervision: at least one trained facilitator per 24 players, with line of sight or camera coverage of every cell and a working two-way radio.
- Medical: a first-aid kit and a named first aider on site; a clear stop word that pauses the run instantly and unlocks all cells.
- Prohibited props: open flame, pyrotechnics, lasers above class 2, restraints, live electrical hazards, and any modification of MazeCrafts locks to prevent manual release.
- Minors: no players under 16, in line with the licence.
Facilitators must complete the pre-run checklist in the console. Skipping it blocks the run from starting.
6. Technical limits and security research
Fair-use ceilings protect shared infrastructure: 60 API requests per minute per workspace, 500 players per concurrent run, 250 MB per uploaded asset and 5 GB of storage per workspace on the Team Enterprise plan. Sustained excess triggers throttling and a notification to the workspace administrator; genuine large events are accommodated on request with 10 business days’ notice.
We welcome good-faith security research. Test only against workspaces you control, never exfiltrate third-party data, do not run denial-of-service or social-engineering tests, and report findings to [email protected]. Researchers who follow these rules will not be pursued and are credited with their permission.
7. Reporting a violation
Players can flag a message from inside the app; the report reaches the facilitator immediately and MazeCrafts within one hour. Anyone else can write to [email protected]. Reports should include the workspace, the run identifier, a timestamp and a description. We acknowledge within one business day, we do not reveal the reporter’s identity to the reported party, and we retain report records for 12 months.
8. Enforcement ladder
We escalate proportionately, weighing severity, intent and history. Steps may be skipped where there is a risk to people.
| Step | Action | Typical trigger |
|---|---|---|
| 1 | In-app notice to the facilitator and removal of the offending content | Minor first-time breach, e.g. an unlicensed image in a clue |
| 2 | Written warning to the workspace administrator with a 7-day remediation window | Repeat content breach, missing safety checklist |
| 3 | Feature restriction — uploads or API access disabled | No remediation, or repeated fair-use breaches |
| 4 | Suspension of the run or workspace | Harassment, safety rule breach, credential misuse |
| 5 | Termination for cause and, where required, referral to authorities | Illegal content, endangerment, deliberate licence circumvention |
9. Appeals
A workspace administrator may appeal any measure within 14 days by writing to [email protected]. Appeals are reviewed by someone not involved in the original decision, and we answer within five business days with reasons. Where a measure is reversed we restore access and, for suspensions longer than 24 hours, credit the affected licence.
10. Changes
We may update this policy to address new abuse patterns or regulatory requirements. Material changes are announced to workspace administrators at least 14 days before they take effect, except where an immediate change is needed to protect people or infrastructure.
Questions about this document?
Our legal team answers within two business days. Procurement teams can request a signable PDF with company details pre-filled.
[email protected]
MazeCrafts Studio GmbH, Ritterstraße 12, 10969 Berlin, Germany
VAT DE352188104 · HRB 214 887 B